Skip to content

Add pdfmake SSRF fix commit reference#8247

Open
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8247from
cookesan:pdfmake-wp52-fix-reference
Open

Add pdfmake SSRF fix commit reference#8247
cookesan wants to merge 1 commit into
github:cookesan/advisory-improvement-8247from
cookesan:pdfmake-wp52-fix-reference

Conversation

@cookesan

Copy link
Copy Markdown

Adds the upstream merge commit for bpampuch/pdfmake#2920 to GHSA-wp52-r2fp-4vmr.

Evidence checked:

  • PR GHSA-qppj-fm5r-hxr3 - How do we proceed with adding new packages? #2920 merged as d20ac0b and adds setUrlAccessPolicy before external URL fetches, with Node interface coverage for denied URLs.
  • Release 0.3.6 names CVE-2026-26801 and documents the URL access policy.
  • npm pdfmake@0.3.6 has gitHead 7737f233, and the 0.3.5...0.3.6 compare contains d20ac0b.
  • The 0.3.6 package archive includes the policy check in src/URLResolver.js.

@github-actions github-actions Bot changed the base branch from main to cookesan/advisory-improvement-8247 June 29, 2026 07:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant